Latest Information Security news from ireland and around the world

Lawsuit Alleges Disney Illegally Tracks Children Via Apps

The Walt Disney Company is fighting allegations this week that its apps fail to safeguard children’s personal information. The move follows a class action lawsuit brought against the company and four others who produce the apps.

According to the complaint (.PDF), Amanda Rushing and her child filed the lawsuit on Thursday in the San Francisco/Oakland division of the United States District Court on the behalf of themselves and others. The suit claims the defendants, The Walt Disney Company, Disney Electronic Content, Upsight, an analytics and marketing platform for mobile apps, Unity Technologies, a video game developer, and Kochava, a mobile analytics platform, violated the FTC’s Children’s Online Privacy Protection Act (COPPA).

Related Posts

August 1, 2017 , 12:39 pm

July 26, 2017 , 8:57 pm

July 26, 2017 , 2:33 pm

The plaintiffs allege that Disney is tracking users, including those under the age of 13, via apps across the internet via a series of specialized advertising software development kits, or SDKs.

The SDKs, embedded into the app’s underlying code, siphon up data such as device personal identifiers associated with children. That information of course is traditionally sold to third parties to create behavioral profiles and advertising schemes.

This is especially the case for Disney Princess Palace Pets, an app for Android and Apple devices made by Disney and is at the crux of the lawsuit.

Rushing claims her daughter, referred to as “L.L.” in the class action suit, used the app while under the age of 13. The lawsuit alleges the game, which lets users “groom, bathe, accessorize, and play” with 10 different pets, is clearly marketed towards children under that age.

The lawsuit goes on to allege that Disney and the defendants collected personal information belonging to children without their parents’ permission. There were no disclosures or mechanisms on the app that prompted the plaintiffs to give their consent, it adds.

“By affirmatively incorporating the SDK Defendants’ behavioral advertising SDKs into their child-directed apps and permitting them to track children by collecting, using, or disclosing their persistent identifiers without verifiable parental consent, Disney violated COPPA,” the lawsuit states.

Disney Palace Pets wasn’t the only app allegedly guilty to tracking users. A slew of nearly 50 other apps such as the Disney Princess: Charmed Adventures, Club Penguin Island, and Disney Emoji Blitz, also contain behavioral advertising SDKs maintained by companies like Upsight, Unity, and Kochava, that “operate in a substantially similar manner,” the lawsuit states.

Michael Sobol, an attorney with Lieff Cabraser Heimann & Bernstein LLP and the author of the complaint, writes that in addition to violating COPPA, Rushing views Disney’s actions as highly offensive and an invasion of her child’s privacy.

The lawsuit isn’t the first to hit Disney, which did not immediately return Threatpost’s request for comment on Monday.

Playdom, a social gaming startup acquired by Disney back in 2010, was forced to pay a $3 million civil penalty for collecting information from hundreds of thousands of children gathered from virtual world websites in 2011. That sum was just a drop in the bucket for Disney; the company had paid over $763 million to acquire Playdom just months before agreeing to the settlement.

The Center for Digital Democracy called out Disney in 2013 after its MarvelKids.com website failed to secure parental consent from children under 13 before tracking and collecting personal information about them.

Disney said at the time it collected that personal information – in some instances their location and persistent identifiers – for internal purposes but that reasoning didn’t cut it for the CDD, which filed a complaint with the Federal Trade Commission in December that year. Disney updated the site’s privacy policy shortly after but it still wasn’t enough in the eyes of the center, which filed a follow up complaint in March stressing the company needs to do more to empower parents and protect children’s privacy.